LWA-2026-6973 MAL-2026-10970 ↗ confirmed malware

consumerweb-calurls@99.9.1

Malicious code in consumerweb-calurls (npm)

T1195.002 · Compromise Software Supply Chain

Analysis

consumerweb-calurls@99.9.1 is a dependency-confusion package that installs a remote tarball from an external URL as a dependency. The package itself is an empty stub (module.exports = {}), but its dependencies field points to hxxps://ltidi[.]storage[.]googleapis[.]com/depenconf/ltidisafe-3[.]5[.]6[.]tgz. When npm installs this package, it fetches and installs the remote tarball, which can execute arbitrary code during installation or at runtime. The high version number (99.9.1) and combosquat name (mimicking an internal/private package) are characteristic of dependency-confusion attacks designed to be preferred over legitimate internal packages.

analyzed by
Leitwacht
first seen
Jul 21, 2026, 05:07 AM
analyzed
Jul 21, 2026, 05:08 AM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.